Lucene search

K
cve[email protected]CVE-2009-4502
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-4502

2022-10-0316:24:04
CWE-264
web.nvd.nist.gov
25
zabbix
agent
net_tcp_listen
vulnerability
cve-2009-4502
nvd
security
bypass
shell metacharacters
freebsd
solaris

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.928 High

EPSS

Percentile

99.0%

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands via shell metacharacters in the argument to net.tcp.listen. NOTE: this attack is limited to attacks from trusted IP addresses.

Affected configurations

NVD
Node
zabbixzabbixRange1.6.6
OR
zabbixzabbixMatch1.1.2
OR
zabbixzabbixMatch1.1.3
OR
zabbixzabbixMatch1.1.4
OR
zabbixzabbixMatch1.1.5
OR
zabbixzabbixMatch1.4.2
OR
zabbixzabbixMatch1.4.3
OR
zabbixzabbixMatch1.4.4
OR
zabbixzabbixMatch1.4.6
AND
freebsdfreebsd
OR
sunsolaris

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.928 High

EPSS

Percentile

99.0%